Horarium

Privacy Policy

Last updated: 24 August 2026

Horarium is operated by Charles Bertin, a sole trader in Australia (ABN 44 136 014 218). This policy explains what personal information we hold, why we hold it, who we give it to, and how you can get at it or correct it.

We are below the $3 million turnover threshold at which the Privacy Act 1988 (Cth) automatically applies to a business. We have chosen to comply with the Australian Privacy Principles anyway, and this policy is written on that basis.

1. Who this policy is about

Horarium is used by two kinds of people, and the difference matters.

Managers sign up themselves and give us their own details.

Staff do not. Their manager enters their details so that rosters can be built. If you are a staff member reading this, your employer put your information into Horarium — we did not obtain it from you, and section 3 explains what we do about that.

2. What we collect

From managers: email address, name, and phone number if provided.

About staff, entered by their manager: name, email address, phone number, job role, hourly cost, and availability constraints — maximum and minimum weekly hours, minimum days off, blocked days, and earliest and latest start times.

Two of these deserve to be named rather than buried in “employment details”:

  • Hourly cost is pay information about an identified person.
  • Blocked days can imply more than they state. The field exists so the roster does not schedule someone when they are unavailable. It is not designed to record why. But a standing block on the same day each week may suggest a religious observance, a caring responsibility or a medical arrangement, and we would rather say so than pretend the inference is not available to anyone who reads it.

Generated by using the service: rosters and shift assignments (who is scheduled when), leave requests, questions asked of the assistant along with the roster context those questions are answered against, and a record of changes a manager makes to a generated roster. Assistant conversations are not stored on our servers — they exist only in your browser for the length of the conversation.

Billing: handled by Stripe. We store a customer reference and subscription status. We never see or store your card number.

Cookies: one, and it is the sign-in session. We use no analytics, no advertising, and no third-party trackers. An anonymous visitor to our marketing site is set no cookie at all. If we enable Cloudflare Turnstile to stop automated sign-in abuse, it will process your IP address for that purpose.

3. Notice to staff (and what we ask of managers)

Because staff information reaches us through an employer rather than from the person themselves, we ask every manager to confirm they are entitled to provide it, and we include a notice in the invitation email each staff member receives, telling them Horarium exists, what is held about them, and how to have it corrected.

If you are a staff member and you were never told, we are sorry — contact us at horariumapp01@gmail.com and we will tell you what is held and route your correction request to your employer.

4. Why we hold it

  • To build, publish and share rosters — the purpose the information was given for.
  • To authenticate you when you sign in.
  • To take payment and manage subscriptions.
  • To improve our scheduling defaults. When a manager changes a generated roster, we record what changed. This trains the industry templates new venues start from. It is a purpose beyond producing your own roster, so we state it separately rather than folding it into “improving the service”.

We do not sell personal information, and we do not disclose it for advertising.

5. Who we disclose it to, and where they are

Horarium runs on services located in the United States. Using Horarium necessarily involves disclosing personal information overseas, and under Australian Privacy Principle 8 we remain accountable for how these providers handle it.

ProviderWhat it receivesCountry
SupabaseDatabase and sign-in records — all stored informationUnited States
VercelApplication hosting; information in transit, and server logsUnited States
AnthropicAssistant questions and the roster context they are answered against, including staff names, roles and constraints; text and photos submitted during setupUnited States
ResendStaff names and email addresses; roster contents in published-roster emailsUnited States
StripeManager email address and billing detailsUnited States
RailwayRoster generation requests, including staff identifiers and constraintsUnited States
CloudflareVisitor IP address, for sign-in abuse prevention, once enabledUnited States

We do not disclose personal information to anyone else, except where required by law.

6. How we protect it

Every table enforces row-level access control, so a venue’s data is reachable only by that venue’s members. Staff cannot alter their own scheduling constraints — only a manager can. Once a roster is published it cannot be altered in the database without being explicitly reopened. Paid features are enforced on the server rather than merely hidden in the interface. All traffic is encrypted in transit.

No system is perfectly secure, and we would rather describe what we actually do than make a general assurance we cannot stand behind.

7. How long we keep it

This section describes what actually happens today, not what we intend to build. We would rather tell you the true position than publish a schedule we do not yet keep.

  • When a manager removes a staff member, that person’s record is deleted straight away. Their sign-in account is deleted too, unless they also work at another venue using Horarium — in which case it stays so they do not lose access to their other roster. This one is automatic.
  • Everything else is kept until someone asks us to delete it. If you cancel your subscription, your venue’s rosters, staff records and settings remain in our database. Nothing is deleted on a timer, and we run no scheduled clean-up of any kind.
  • Sign-up attempts that were never completed — an email address that requested a code but never created a venue — are also kept.
  • Billing records are held by Stripe under their own retention terms, and we keep the account record showing your subscription status.

You can ask us to delete your data at any time, whether or not you are still a customer. Write to horariumapp01@gmail.com and we will delete it and confirm when it is done. We do this by hand, so allow up to 30 days.

We know that indefinite retention is not where we want to be, and automatic deletion after cancellation is something we intend to build. Until it exists, this section says so.

8. Getting at your information, and correcting it

You may ask what we hold about you and ask us to correct it. Write to horariumapp01@gmail.com and we will respond within 30 days.

If you are a staff member, one thing is worth knowing. You can sign in and see your own roster, but you cannot edit your own hours, pay rate or availability — deliberately, so that the constraints your employer sets cannot be changed by the person they apply to. That means a correction request has to go through your manager, or through us. Ask us and we will pass it on.

9. Complaints

If you think we have mishandled your personal information, contact horariumapp01@gmail.com. We will acknowledge within 5 business days and respond within 30 days.

If you are not satisfied, you can complain to the Office of the Australian Information Commissioner — oaic.gov.au, or 1300 363 992.

10. Changes

If we change this policy we will update the date above, and we will tell account holders by email before any change that materially affects them takes effect.

11. Contact

Charles Bertin (ABN 44 136 014 218)
128 Womerah Avenue, Darlinghurst NSW 2010
horariumapp01@gmail.com